Skip to content
Data & Signals

After 1.2 Million People’s Data Were Compromised, Latvia’s CSDD Faces a Leadership Crisis

After 1.2 Million People’s Data Were Compromised, Latvia’s CSDD Faces a Leadership Crisis

A cyberattack on Latvia’s Road Traffic Safety Directorate (CSDD) has developed into a wider governance crisis after authorities disclosed the scale of the breach and shortcomings in the institution’s cybersecurity arrangements.

Data affecting 1.2 million individuals and around 200,000 legal entities were obtained by an attacker between 8 and 10 August. The compromised records date back to 2008 and may include personal identification numbers, names, addresses, vehicle registration numbers, payment dates and amounts.

CSDD says phone numbers and email addresses were not affected. It had earlier also said that client usernames and passwords had not been compromised.

The immediate risk is fraud. CERT.LV warned that combining a person’s name, identification number, vehicle details, address and information about previous payments could allow criminals to build highly personalised phishing and social-engineering attacks.

But the incident has also raised a more fundamental question about how CSDD managed cybersecurity risk.

CERT.LV said the attack exploited a vulnerability in an internet-accessible CSDD system and that several mandatory cybersecurity requirements had not been implemented, including multi-factor authentication and penetration testing.

CERT.LV also said it had no visibility into the affected infrastructure because CSDD had chosen not to use its services, citing, among other reasons, its own capabilities.

The political response has escalated rapidly.

Latvian President Edgars Rinkēvičs said the mass data breach represented a significant national security threat and that CSDD’s management should not continue in office under the circumstances.

Prime Minister Andris Kulbergs has ordered an assessment of the responsibility of CSDD’s management board and supervisory council, while Transport Minister Rihards Kozlovskis has launched an expedited internal investigation.

Aivars Aksenoks, chairman of CSDD’s management board, however, has said he does not intend to resign and sees no wrongdoing by the board, telling Latvian Television that its “conscience is completely clear”.

That position sits uneasily beside CERT.LV’s finding that mandatory security requirements had not been met.

Cybersecurity concerns around CSDD are also not entirely new. In 2018, Raimonds Skuruls identified a vulnerability in a CSDD system. He later sought €1,000 in connection with disclosing its technical details, a dispute that developed into a long-running criminal case over an extortion charge.

There is no evidence that the vulnerability identified in 2018 had any technical connection with the August 2026 attack. The earlier case is relevant for a narrower reason: it provides historical context for questions about how CSDD has dealt with externally identified security weaknesses.

The government response is now extending beyond CSDD. Following cyber incidents at both CSDD and Latvijas Valsts meži, authorities have ordered broader reviews of critical state IT infrastructure, including penetration testing, security audits and expanded use of CERT.LV monitoring systems.

The CSDD case therefore increasingly looks like more than a large data breach.

The central question is whether an institution holding sensitive information on a substantial share of Latvia’s population had an adequate system for identifying, testing and independently overseeing its own cyber risks.